Cross-site Scripting Vulnerability in Themeum WP Crowdfunding Plugin
CVE-2025-31892
6.5MEDIUM
What is CVE-2025-31892?
The Themeum WP Crowdfunding plugin is vulnerable to a Cross-site Scripting (XSS) issue that arises from improper neutralization of input during web page generation. This vulnerability allows for the potential storage and execution of malicious scripts within the context of the user’s session, exposing users to attacks when they interact with affected content. The vulnerability impacts versions of WP Crowdfunding from n/a up to 2.1.13, emphasizing the importance of updating to safeguard against potential exploits.
Affected Version(s)
WP Crowdfunding <= 2.1.13